SAP security note 1583286, "Possible Disclosure of Authorization Verifications in RSTXSCRP", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability has been identified in RSTXSCRP that allows a malicious user to potentially disclose authorization verifications. By exploiting this vulnerability, an attacker can impersonate a legitimate user, leading to unauthorized access.
Solution
To address this vulnerability, implement the necessary corrections using the Note Assistant or import the relevant Support Package.
CVSS
Score 2.3 Vector: AV:A/AC:M/AU:S/C:P/I:N/A:N
References
- RSTXR3TR: Implementing authorization for import
- Cascading Font settings
- RSTXSCRP: Version check when importing device type
- RSTXSCRP: No transport request for TSP06POT
- RSTXSCRP: Warning for incorrect printer code page
- Character set problems in RSTXSCRP and RSTXR3TR
Affected components
- SAP_BASIS 46C
- SAP_BASIS 620 to 640
- SAP_BASIS 700 to 730
Full note on SAP: SAP Support Launchpad note 1583286
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



